All articles Advanced signals

Onboarding Velocity Attacks: Catching Mass Account Creation at Neobanks

Neobank onboarding is designed to be fast and self-serve, which means it can be driven at machine speed by anyone with a script and a proxy pool. When that happens, hundreds of accounts appear before a human notices.

These velocity attacks farm accounts for mules, promos, and fraud staging. Catching them requires measuring signups at the device level, where rotation is hardest to fake.

Anatomy of a velocity attack

The attack is industrial: identity, network, and browser are all rotated to make each signup look fresh.

  • Rotated identities. Stolen or synthetic identity kits cycle through the signup form.
  • Proxy rotation. Residential and datacenter proxies give each account a different IP.
  • Automation. Headless browsers and form-fillers submit far faster than any human.
  • Burst timing. Hundreds of accounts created in a tight window, often off-hours.

Any single signup can pass. The attack only reveals itself across the burst.

Why IP-based defenses fail

The instinct is to rate-limit by IP, but that is the first thing attackers defeat.

  • Cheap IP rotation. Residential proxy pools offer effectively unlimited fresh IPs.
  • Shared legitimate IPs. Carrier-grade NAT means real users share IPs, so aggressive limits hurt them.
  • No identity persistence. An IP says nothing about whether the same operator is behind two signups.

Durable defense needs an identifier the attacker cannot cheaply mint anew.

Device-level signals that hold up

The device is the anchor that survives identity and IP rotation.

  • Velocity per visitorId. A stable device identifier submitting many signups exposes the burst that IP rotation hides.
  • Automation markers. Headless browsers, spoofed environments, and emulators separate scripts from people.
  • Device reuse across identities. One device behind many nominally different applicants is the core farming signal.
  • Network anonymization. VPN, proxy, and datacenter flags catch the rotation infrastructure itself.

Prynt provides these as server-side Smart Signals bound to a persistent visitorId, so device-level velocity becomes a rule you can enforce. Its bot detection surfaces the automation driving the burst.

Stopping the burst without blocking real signups

Neobanks need clean onboarding to convert, so the aim is surgical.

  • Rate limit by device. Enforce velocity on the visitorId, not just the IP.
  • Challenge automation. Route sessions with automation or emulator markers to step-up, not straight through.
  • Cluster and hold. Freeze bursts of accounts linked by a shared device set pending review.
  • Feed outcomes back. Confirmed farmed accounts propagate device risk to catch the next burst instantly.

Because the signal is present on the first page load, a genuine single applicant sails through while the farm hits a wall.

Measuring the defense

Prove the control is working, not just firing.

  • Accounts per device. Watch for clusters that exceed any plausible household.
  • Automation rate at signup. Track the share of sessions flagged as scripted.
  • Downstream fraud by cohort. Confirm that high-velocity device cohorts convert into mules and abuse.
  • Clean-signup friction. Keep challenge rates on legitimate applicants near zero.

The downstream cost of missing it

Farmed accounts are rarely the end goal; they are inventory for later fraud.

  • Mule supply. Bulk accounts become the receiving legs of laundering chains.
  • Promo and referral drain. Farms harvest signup bonuses at scale.
  • Fraud staging. Aged farmed accounts are sold on for takeover-resistant abuse later.

Bringing it together

Onboarding velocity attacks win because self-serve signup runs at machine speed and IP-based limits are trivial to rotate around. The device is the one identifier an attacker cannot cheaply regenerate, which makes device-level velocity the control that actually holds.

Rate limiting and clustering on a stable visitorId stops mass account creation before those accounts are ever funded, without taxing real customers. Prynt is free to start and scores every signup server-side. Start free at pricing.

Try it free

Prynt is device intelligence with a free tier — visitor IDs, bot & fraud Smart Signals, and behavioral biometrics, powered by a cross-site network. Start free.

Keep reading